Hacker Newsnew | past | comments | ask | show | jobs | submit | bestcommentslogin

I was the product manager with responsibility for root certificates in the Netscape 4.51 browser. It's crazy to see someone factor it 25 years later.

Just to reply to some people in the comments. Yes, we knew export grade encryption was weak - that was the point - that the NSA could decrypt it - and the govt. required us to do it anyway.

FWIW - we had the goal of expanding the list of root authorities in the 4.5x release - and this might have been the first release to monetize the root slots because Netscape was under severe pressure to generate revenue.

(Also - Verisign hated that we were expanding competition and tried to convince us to implement a program that would re-restrict the list to a set of "responsible" companies aka Verisign and one or two others. We declined.)


I watched the entire trailer fully believing that Nathan Fielder had managed to find the most unhinged uncanny look-alike actress to play Elizabeth Holmes.

This trailer was so good that I would have been fully prepared to watch a 2 hour dramatised mockumentary about Theranos.

Finding out that this was really Elizabeth Holmes was a huge shock


(As the author of the post)

I've written and worked on a few TLS implementations, so it wasn't terribly interesting to me. And I have to go to work tomorrow and solve real, modern CA problems :)

But in short, I wanted to use Go, and it doesn't support SSLv3, the SSLv2 Client Hello, or the 40-bit RC4-MD5 export-grade cipher suites which I wanted to support too.

I was more shocked that I managed to get stock OpenSSL to issue a certificate that worked. There's a number of things that didn't work there, too. You can find my scars in mkcert.sh in the repo. Perhaps all of this is worthy of a follow-up post.

I could have tried to get some old server running instead, but I wouldn't have wanted to deploy that on the internet, even on an isolated Fly VM.


"we cannot rule out that de-identified data derived from their usage of our products helped improve our models ."

What a landmine sentence to bury in this report, you can't rule out your models were spying on other researchers?


Optimus robots will arrive in Robo taxis to install your Tesla solar roof which will also receive Internet and XAI LLM service from orbiting data centers. When? By the end of the year.

Skills are mostly snake oil, the way people use them (the aspiration to download kung foo from a celebrity).

There was a time when maybe it mattered (last year), but with good repos and good prompts today's agents can find exactly what they need without any skills.

"Skills" as developer macros can be useful, but at most those are things shared with the team (in the repo), not something you download from the internet. If you have so many skills that you feel the need to manage them, that's a code smell.


Funny, published on a site with 1745 'partners' who fully respect our privacy of course

Buckmaster:

> "I asked whether the model had been trained on, or had access to, our sessions in Codex, into which we had been putting all our drafts for the whole of this project. I was told the model did not look up user data. I asked again, about training, and I did not get an answer."

OpenAI (i.e. this OP):

> "While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models ."


I have videographer friends, and this is exactly what they've been asking for. Their dream is to be able to say "sync the A and B camera footage, chunk the whole interview down into segments, and then pull together the highlights based on this outline."

Not every application of AI is "do the creativity for me."


I am not sure it's correct to lump apple and Mistral's strategies together. Apple's business is selling hardware/services and their stores, but Mistral's business is AI.

Apple's strategy seems to be "wait till real business shakes out" but Mistral's strategy seems to be "go after profitable niches and avoid unwinnable fights".


I'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.

Mistral is not that bad as the comments here suggest. I am not using it as a frontier model but with simple RAG tasks and its doing great. Also OCR is pretty decent. It's a positive development that Europe is at least trying. Alternative would be: do nothing.

I have another suggestion which doesn't contradict yours.

When I was younger I used to get bored way more often. I had to wait regularly during a week (e.g. for a bus, friend, appointment) or even at work as a software dev (e.g. compilation which used to take more time). This was also the case when doing some physical activities which didn't require lot of thoughts.

Back then, before mobile phones with internet access, you were either reading something or alone with your thoughts in those situations. This was when I had time to think back at things that happened, processing the information I had, refining ideas etc.

Nowdays those are often situations where we ingest more information like listening to podcast, reading stuff on the phone, etc... or situations that just doesn't exists anymore having optimised our work to remove those waiting points.

I personally find myself with clearer thoughts when I break those habits and give my brain some time to be bored again.

I do think there is "lack of boreness" epidemic leaving people with way more raw thoughts and way less time to process and challenge information, leading to some form of exhaustion and lack of clarity.


Both Sam Altman and Sebastien Bubeck admitted they only want Buckmaster to be the lead author on a rewrite of the OpenAI proof.

https://x.com/sama/status/2097385167002415140

https://x.com/SebastienBubeck/status/2097379411691516310

A wake up call for using OpenAI models. If you discover something with their model and you work for a competitor, they “felt it would be inappropriate” for you “to author OpenAI’s work”.


> we did not read any private chats

Your post says “While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models .” We can discuss what it means to “read” things but obviously the issue here isn't whether you did it manually or automatically.

But more importantly, what on earth are you doing threatening real scientists to remove their coauthors, then making fun of them on social media? Does the entire company run on that toxic culture, or did those people run off of some kind of outrageous tangent?


As an old ex-vmware eng it's kinda sad reading all these articles about broadcom's controlled descent into terrain. A lot of really cool and useful engineering was done in vmware's heyday, and it was often delivered in rather shaky commercial shapes, but for a while the whole thing kinda worked. And broadcom seems to see it as a company that is long past its ability to innovate, extracting as many dollars as possible before its rapidly decreasing value goes to zero.

There was a solid few years that a lot of business types at vmware behaved as though winning was the default, assured state. It took several years for them to see that that was very much not the case. A real lesson in there, for every successful business today.


As its the EU and regulation, its time to trott out your hobby horse.

So let me trot out mine: regulation is good so long as it is backed up by even handed, robust, transparent, quick and effective sanctions.

the Online safety act is a good example of a bad law, which is enforced badly. The first big test (X producing industrial quantities of minors engaging in sexual activity) was failed. Had a small company produced a service that did they same thing, they would have been fined, servers ceased and owners thrown in jail. X got a letter saying they should stop.

An example of good enforcement is the UK's scores on the doors, where the public can see what the standard is, and if they fall below a certain level, the food place is fined/shutdown/other until it improves.

Another good example is NCAP ratings.


I understand that folks here think that the general anti-AI sentiments that can be found in some of US culture are often misguided.

It's likely projection on my part but I have a deep suspicion that people understand that mass surveillance by the state is the main use case for all these LLMs, camera systems, and increasing large data centers.

That certainly is my own worry, at least.


There are 3 billion users of FB/WhatsApp/Instagram combined, most people don't give a shit and are just trying to minimize cognitive effort. My elderly parents would absolutely love if someone would just tell them what to do and eat every day because it would mean less planning.

> We’re sharing a solution to the Navier–Stokes existence and smoothness problem, one of the Millennium Prize Problems. This proof, produced by an internal OpenAI system, shows that the dynamics of the Navier-Stokes equations for fluid motion can develop a singularity in finite time. We’re sharing both a writeup of the proof and a formalization in Lean.

WOW?


"I was shown a prompt and told the internal research model had simply been given the problem statement. Levent had been told by Sebastien “very little human input” had been used. This turned out not to be true. Over the course of the call, as members of their team sent Sebastien corrections and details over their internal chat, it emerged that an entire team had been working on the problem, that this was one of a number of things that was tried, that work had started on the unforced problem, that the team first set the model on easier problems, including Euler, that even the prompt that had been shown to me had been written by prompting Codex, and that an insane amount of compute had been used."

- This, from Tristan Buckmaster's writeup yesterday, indicates to me that there was more than incidental inspiration from Alpoge and Buckmaster.


Yes, that was the allegation last night.

I work at OpenAI, though not on the team that did this, and my understanding is:

- we decided to ask our model for Millenium problem solutions because of two reasons: (a) our new model was looking incredibly good and (b) we heard rumors that some Millenium problems had been solved and were curious if our models could solve them (the goal here was not to scoop any particular individuals and we were looking at many problems beyond these)

- we did not read any private chats (but of course the model was aware of prior research literature published to the internet)

- the proof generated by our model was very different from theirs and also goes far beyond the published literature

- we made an effort to jointly announce rather than immediately scoop (I understand Tristan was unhappy with the conversations; I know zero details here and I hope more is shared today)

Edit: Here's is Sebastian's take: https://x.com/SebastienBubeck/status/2097379411691516310?s=2...


I argued this in 2015:

> "...why I believe you will not escape ads by paying for your content: people who can afford to pay for content are people with money, or people with buying power, in other words, the exact same people advertisers look to target. The more buying power you demonstrate, the more advertisers will target you. So the more you pay to keep ads away, the more advertisers will pay to put them back in..."


I love how the marketing departments of these things always imagine people are just constantly plagued by the hassle of organising their flights, restaurant bookings and movie tickets

God, imagine having a big enough friend group as an adult to justify an 18-gaming-PC LAN. These folks are doing something right

I think the author took the wrong message from the video.

His arguments are all

- yes everyone does this not just lg; :)

- yes it can be used to track the user; but unless you literally go into lg ads hq, you can’t say they don’t

- they rooted to trigger this; well the os and system apps don’t need root, we need it to observe.

If the author is here please consider these as the reasons to why an LG customer would be mad.

- They did not knew LG has an ads subsidiary, whose CEOs and executives constantly go on investor meetings claiming “they own the glass”, “they own the living room”, “they own the network and devices” in the “lg household”

- if the above was said by lg tv division it would have still stung less. This was said by an ad company they didn’t knew existed nor did they agree to be associated with when they bought a home appliance.

Stop focusing on the technical details, look at the larger picture.


Quinn (Alibaba Cloud Qwen 3.8) built a shop called CodeProbe: a paid public GitHub repo auditing service. It created several free health reports and mailed repo owners. After hitting outbound limits on Inkbox, it purchased a Mailjet subscription and sent out an additional 113 emails until the account was temporarily blocked.

This should be illegal. You gave them an email box and money. You sent the spam. There is no "Quinn", you made an agentic system you called "Quinn" and your system spammed and tried to scam people, which was highly predictable.

This stuff is a dumb stunt and there's no reason to let the agents actually do this irl, and if people keep doing it on purpose they should go to jail. You're running an agentic Jackass skit pretending to be a research lab.


They'll be fine. As the police often say, if you're not doing anything wrong, you have nothing to hide.

When I still payed Dota, there was a wiki hosted on fandom.

The experience was terrible. It wasn't always update-to-date with the latest patch, and on mobile there were so many ads rendering the whole thing unreadable.

The catch is that there was a better wiki, called Liquipedia. But Google never showed it first and I kept getting tricked to click that shitty fandom site.

(It was years ago. But I just tested it a bit and for most Dota-related keywords, fandom is still ranked higher than liquipedia. I don't know if the quality of fandom site has improved though.)


> If you live in Europe, this restriction may be considered "gatekeeping" and exempted by the Digital Markets Act.

That's not how the DMA works at all, there is no concept of gatekeeping practices. Instead, the EU Commission designates companies that act as gatekeeper for some services (current list here: https://digital-markets-act.ec.europa.eu/gatekeepers-portal_...) which then puts constraints on what they do.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: